PkgRadar

PyPI · pypi.org

rh-model-signing

Remote Payload: matched "cUrl "

Why PkgRadar flagged 1.0.3

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · rh_model_signing-1.0.3/generate-trust-config.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.3Review122026-06-08

Block this in CI

PkgRadar gates rh-model-signing (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi rh-model-signing==1.0.3